@kernlang/vue
Kern Vue/Nuxt transpilers — Vue 3 SFC + Nuxt 3 output
41
Versions
AGPL-3.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
cukasn
Keywords
kernllmvuenuxttranspilerai
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:vite | AI (typosquat): Scoped @kernlang package; not an impersonation of vite. Edit-distance match is coincidental. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @kernlang package; not an impersonation of yup. Edit-distance match is coincidental. | ai | |
| dependencies | unvetted-dep:@kernlang/core | AI (dependencies): Internal sibling package within the same @kernlang ecosystem; stable dependency pattern. | ai |
Versions (showing 41 of 41)
| Version | Deps | Published |
|---|---|---|
| 4.5.0 | 1 / 0 | |
| 4.1.0 | 1 / 0 | |
| 4.0.0 | 1 / 0 | |
| 3.5.8 | 1 / 0 | |
| 3.5.7 | 1 / 0 | |
| 3.5.6 | 1 / 0 | |
| 3.5.5 | 1 / 0 | |
| 3.5.4 | 1 / 0 | |
| 3.5.3 | 1 / 0 | |
| 3.5.2 | 1 / 0 | |
| 3.5.1 | 1 / 0 | |
| 3.5.0 | 1 / 0 | |
| 3.4.9 | 1 / 0 | |
| 3.4.8 | 1 / 0 | |
| 3.4.7 | 1 / 0 | |
| 3.4.6 | 1 / 0 | |
| 3.4.5 | 1 / 0 | |
| 3.4.4 | 1 / 0 | |
| 3.4.3 | 1 / 0 | |
| 3.4.2 | 1 / 0 | |
| 3.4.1 | 1 / 0 | |
| 3.4.0 | 1 / 0 | |
| 3.3.9 | 1 / 0 | |
| 3.3.8 | 1 / 0 | |
| 3.3.7 | 1 / 0 | |
| 3.3.6 | 1 / 0 | |
| 3.3.5 | 1 / 0 | |
| 3.3.4 | 1 / 0 | |
| 3.2.3 | 1 / 0 | |
| 3.1.9 | 1 / 0 | |
| 3.1.8 | 1 / 0 | |
| 3.1.7 | 1 / 0 | |
| 3.1.6 | 1 / 0 | |
| 3.1.5 | 1 / 0 | |
| 3.1.4 | 1 / 0 | |
| 3.1.3 | 1 / 0 | |
| 3.1.2 | 1 / 0 | |
| 3.1.1 | 1 / 0 | |
| 3.1.0 | 1 / 0 | |
| 3.0.0 | 1 / 0 | |
| 2.0.0 | 1 / 0 |
v4.5.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.